pfsense openvpn?
The following question: When the client contacts the remote VPN server, it presents its certificate, which was signed using a CA certificate. This certificate was created using pfsense. Since this CA is not a public certification authority, this CA certificate must be integrated into the client and trusted. This is how it is with https. This all happens during setup, so I don't even notice it.
Each device has its own list of CAs that it trusts. It only accepts certificates from trusted CAs. You can usually delete or add CAs from your Trust Storage yourself.
If you want to build your own VPN, it may be useful to sign the certificates with your own CA. You can then deposit the CA certificate in the Trust Storage to all devices.
I’ve never worked with pfsense, I’m usually on OpenWRT, but all of this will be possible. I have under https://docs.netgate.com/pfsense/en/latest/certificates/ca.html an overview of the CA management found.